Area II: Assessing Risk and Developing a Planned Response
This area follows planning from the overall strategy to a risk-based plan: understanding the entity and its controls, setting materiality, assessing the risk of material misstatement due to fraud or error, and deciding how to respond. It also covers using the work of others and several specific risk areas, including laws and regulations, estimates, related parties, and the Uniform Guidance thresholds that trigger a single audit.
Planning and understanding the entity
The overall audit strategy sets the scope, timing, and direction of the audit, and the audit plan turns it into specific risk assessment and further procedures. Understanding the entity covers external factors such as industry, regulation, and the economy, and internal factors such as ownership, governance, strategy, and technology. For issuers, Sarbanes-Oxley adds governance duties the auditor must understand, including the audit committee's authority over the auditor and management's certifications.
Internal control, IT and service organizations
The system of internal control has five components, matching the COSO framework, and every system has inherent limitations such as collusion and management override. The auditor distinguishes general IT controls, which support the IT environment as a whole, from information-processing controls that act on individual transactions. When an entity outsources processing, the auditor uses the service organization's SOC 1 report and considers the controls the user entity itself is expected to operate.
Materiality and the risk of material misstatement
Materiality for the financial statements as a whole starts from a benchmark and a percentage the auditor chooses, and performance materiality is set lower to allow for misstatements that go undetected. Under SAS No. 145, the auditor assesses inherent risk and control risk separately at the assertion level. Inherent risk is placed on a spectrum using inherent risk factors, and risks close to the upper end are significant risks. Fraud risks and the risk of management override call for specific responses.
Using others and specific risk areas
The auditor may use the work of internal auditors and specialists but keeps sole responsibility for the opinion. Laws and regulations fall into two groups, each with its own required procedures. Accounting estimates call for attention to management bias, and related parties call for alertness to relationships management has not disclosed. For entities that receive federal awards, the Uniform Guidance determines when a single audit is required and how major programs are selected.
Keep going: the full CPA Exam — Auditing and Attestation (AUD) guide covers every section of the exam. CPA AUD Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Practice stays free. The full CPA Exam — Auditing and Attestation (AUD) study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.